NIST Control Families Flashcards
AC
Access Control
Account mgmt, access enforcement into and within system, separation of duties, least privilege, logons, remote access, wireless access, mobile device access.
AT
Awareness Training
Role-appropriate security awareness training, training records.
AU
Audit and Accountability
Log events, analyze logs, protect logs, ensure non-repudiation of logs.
CA
Security assessment and authorization
Assessment plan, pen testing, assessments, POA&M, OA authorization.
CM
Configuration Management
Baseline and configuration management, inventory, sw installation and usage restrictions (licensing).
CP
Contingency planning
Backup and restore, alternate sites.
IA
Identification and authentication
Technical controls. User and device identification (ex: RADIUS).
IR
Incident response
IR planning, training, testing, incident handling, incident reporting.
MP
Media protection
Media marking, transport, sensitization and use policy.
PE
Physical and environmental protection
Guards, guns and gates. Emergency power, fire protection, temperature control.
PL
Security planning
SSP, SECONOPS, info sec architecture,
PM
Program management
PS
Personnel security
Administrative controls. Position risk, screening, terminations, NDAs.
RA
Risk assessment
Security categorization, risk assessments, vulnerability scanning, technical surveillance countermeasures survey.
SA
System and services acquisition
Administrative controls. Adequate budgeting, software development life cycle, sw engineering principles, acquisition process, supply chain protection, external developer services